Area for Improvement
License declarations across the workspace packages.
Observed behavior
Four declarations, three different answers, and the inconsistency lands on the one package that is currently publishable:
| Location |
Declares |
LICENSE (repository root) |
Apache License 2.0 |
package.json (repository root) |
no license field at all |
plugins/plugin-radius/package.json |
Apache-2.0 |
plugins/plugin-radius-backend/package.json |
Apache-2.0 |
packages/rad-components/package.json |
ISC |
The root package.json is "private": true, so a missing license field there is not fatal, but it does mean the repository's own manifest asserts nothing.
The part that matters: @radapp.io/rad-components declares ISC and is not private. It is the only package in the workspace that is currently publishable, and it is the one that disagrees with the repository's LICENSE file. Anyone consuming it from a registry would be told ISC while the repository it came from says Apache-2.0.
This is almost certainly an unreviewed default from whatever scaffolded the package rather than a deliberate choice — ISC is the npm default when no license is specified interactively.
Desired behavior
Every package declares the license the project actually intends, consistent with the root LICENSE file. If Apache-2.0 is correct, rad-components is corrected and the root manifest gains an explicit license field so the intent is stated rather than inferred.
This needs a maintainer decision rather than a drive-by fix, since changing a declared license on an already-published package has implications beyond the repository.
Proposed Fix
- Confirm the intended license for
@radapp.io/rad-components, including for versions already published under ISC.
- Align the package manifests.
- Add
"license" to the root package.json.
Worth resolving before the plugin-publication work lands, because that work adds more published packages and the design also moves code between repositories — which is a bad time to have an unresolved license question.
Additional context
Pinned by PU-18 in plugins/plugin-radius/src/packaging.test.ts, added in nicolejms#1, which records the present state and fails if it drifts further.
Noted as open decision 2 in docs/design/2026-09-dashboard-plugin-test-plan.md.
Area for Improvement
License declarations across the workspace packages.
Observed behavior
Four declarations, three different answers, and the inconsistency lands on the one package that is currently publishable:
LICENSE(repository root)package.json(repository root)licensefield at allplugins/plugin-radius/package.jsonApache-2.0plugins/plugin-radius-backend/package.jsonApache-2.0packages/rad-components/package.jsonISCThe root
package.jsonis"private": true, so a missinglicensefield there is not fatal, but it does mean the repository's own manifest asserts nothing.The part that matters:
@radapp.io/rad-componentsdeclares ISC and is not private. It is the only package in the workspace that is currently publishable, and it is the one that disagrees with the repository'sLICENSEfile. Anyone consuming it from a registry would be told ISC while the repository it came from says Apache-2.0.This is almost certainly an unreviewed default from whatever scaffolded the package rather than a deliberate choice —
ISCis the npm default when no license is specified interactively.Desired behavior
Every package declares the license the project actually intends, consistent with the root
LICENSEfile. If Apache-2.0 is correct,rad-componentsis corrected and the root manifest gains an explicitlicensefield so the intent is stated rather than inferred.This needs a maintainer decision rather than a drive-by fix, since changing a declared license on an already-published package has implications beyond the repository.
Proposed Fix
@radapp.io/rad-components, including for versions already published under ISC."license"to the rootpackage.json.Worth resolving before the plugin-publication work lands, because that work adds more published packages and the design also moves code between repositories — which is a bad time to have an unresolved license question.
Additional context
Pinned by
PU-18inplugins/plugin-radius/src/packaging.test.ts, added in nicolejms#1, which records the present state and fails if it drifts further.Noted as open decision 2 in
docs/design/2026-09-dashboard-plugin-test-plan.md.